Seedance 2.0 — agentic threat model
Seedance 2.0 is a low-autonomy AI video generator with minimal agentic capabilities, presenting primary risks around non-deterministic output generation, potential deepfake creation, and abuse of GPU resources rather than systemic agentic failures.
OWASP AIVSS score rationale
| Autonomy of Action | 0.10 | |
| Goal-Driven Planning | 0.10 | |
| Self-Modification | 0.00 | |
| Dynamic Tool Use | 0.10 | |
| Persistent Memory | 0.00 | |
| Contextual Awareness | 0.20 | |
| Dynamic Identity | 0.00 | |
| Multi-Agent Interactions | 0.00 | |
| Non-Determinism | 0.70 | |
| Opacity & Reflexivity | 0.60 |
Scored with the canonical OWASP AIVSS formula (AIVSS calculator reference); agentic risk factors estimated from the agent’s described capabilities.
MAESTRO 7-layer threat model
Per-layer threats for this agent. Layers tagged “not certain from listing” are general, caveated commentary where the public description didn’t pin that layer.
Uses the ByteDance Seedance 2.0 AI Video foundation model. Primary threats include adversarial prompt injections to bypass safety filters (e.g., generating NSFW or copyrighted content) and potential model extraction/stealing.
Not certain from the listing — details regarding video asset storage, user prompt logging, and data privacy/provenance are not specified in the public directory.
Not certain from the listing — the tool functions as a direct generator rather than an agentic framework, meaning threats like tool misuse or complex memory poisoning are likely minimal or absent.
Not certain from the listing — hosted as an online web service, exposing it to standard web application vulnerabilities and potential GPU resource exhaustion attacks, but specific infrastructure details are unknown.
Not certain from the listing — there is no mention of output monitoring, automated content moderation guardrails, or abuse detection mechanisms to prevent malicious video generation.
Not certain from the listing — being closed-source and freemium, it lacks public documentation regarding compliance with data protection laws (GDPR/CCPA) or copyright safety policies.
Not certain from the listing — operates as a standalone horizontal utility with no indicated multi-agent collaboration or marketplace integrations.
MAESTRO — the 7-layer agentic threat-modeling framework (Cloud Security Alliance / Ken Huang).